Jump to content

Unsure about infection


Recommended Posts

Hello,

I have MBAM pro installed with real-time protection enabled (MBAM and MSE have been installed for months and always updated daily). I also run MSE and make sure I always use a normal user account. Two days ago I decided to give my computer a sweep with Hitmanpro, like I do sometimes just to make sure nothing has slipped through. I was alarmed at the result which said I had an infection in my windows temp folder. Here is the actual log file from Hitmanpro -


HitmanPro 3.7.0.185
www.hitmanpro.com

Computer name . . . . : PC-PC
Windows . . . . . . . : 6.1.1.7601.X86/4
User name . . . . . . : pc-PC\pc
UAC . . . . . . . . . : Enabled
License . . . . . . . : Trial (Expired)

Scan date . . . . . . : 2013-01-12 01:58:59
Scan mode . . . . . . : Normal
Scan duration . . . . : 48s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No

Threats . . . . . . . : 1
Traces . . . . . . . : 80

Objects scanned . . . : 1,085,506
Files scanned . . . . : 50,256
Remnants scanned . . : 415,950 files / 619,300 keys

Malware _____________________________________________________________________

C:\Windows\Temp\TMP00000025127610CA337AB5EE
Size . . . . . . . : 524,288 bytes
Age . . . . . . . : 0.0 days (2013-01-12 01:57:05)
Entropy . . . . . : 6.5
SHA-256 . . . . . : DCCD18C15449954F5C4611220081F952F4B384AC398DE25773DA3C43503870F0
Product . . . . . : Windows Live Client
Publisher . . . . : Microsoft Corporation
Description . . . : Windows Live Client Shared Platform Module
Version . . . . . : 15.4.3555.0308
Copyright . . . . : © Microsoft Corporation. All rights reserved.
> Ikarus . . . . . . : Worm.Autorun!IK
Fuzzy . . . . . . : 112.0

I found this crazy, as MBAM never said anything and MSE didn't either.

I cleaned out my temp internet files, and after scanning everything again (this time with Eset online and Superantispyware) nothing came up. I'm out of my depth so I'm wondering am I infected?

Thank you.

Link to post
Share on other sites

Hi MrCharlie,

Thank you for the welcome and the reply.

I don't think I explained myself very well; After running the Hitmanpro scan and finding the worm, I panicked and cleaned my temp folder. After that I ran the Eset and SAS scan. They didn't find anything. If this was a worm and I'm infected, wouldn't there be some traces? Surely MBAM would have flagged this infection? I'm not sure on how to go one, as I use my computer for accounting and can't have it compromised.

Thanks again,

John.

Link to post
Share on other sites

OK, we'll run some scans.......

Welcome to the forum, please start at the link below:

http://forums.malwar...?showtopic=9573

Post back the 2 logs here.....DDS.txt and Attach.txt

<====><====><====><====><====><====><====><====>

Next.......

Please remove any usb or external drives from the computer before you run this scan!

Quit all running programs.

Please download and run RogueKiller to your desktop.

For Windows XP, double-click to start.

For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system.

When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

MrC

Please don't run any other scans, download, install or uninstall any programs while I'm working with you.

Please stick with me until I give you the "all clear".

------->Your topic will be closed if you haven't replied within 3 days!<--------

(If I don't respond within 24 hours, please send me a PM)

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.